← Carolina Clear Tech

Cyber Threat Brief

2026-04-19

Listen to this brief (13:26)

Download MP3
Show Notes

Show Notes - 2026-04-19

Stories Covered

CVEs Referenced

CVE-2026-4519, CVE-2026-4786, CVE-2026-5160, CVE-2026-6100

Indicators of Compromise

IP Addresses: 9.0.1.0

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - 2026-04-19

Today: A critical RCE flaw in protobuf.js (50M weekly downloads) has proof-of-concept exploit code published. Microsoft is tracking cross-tenant Teams impersonation attacks that establish remote access and pivot to domain controllers via WinRM. Los Angeles County schools are investigating fraudulent tax filings after potential W-2 theft affecting 150,000+ employees.

Critical Alerts

Critical flaw in Protobuf library enables JavaScript code execution

A critical remote code execution vulnerability in protobuf.js (GHSA-xq3m-2v4x-88gg) affects the widely used JavaScript implementation of Google's Protocol Buffers, which averages 50 million weekly downloads from npm. The flaw is caused by unsafe dynamic code generation where the library builds JavaScript functions from protobuf schemas by concatenating strings and executing them via the Function() constructor without validating schema-derived identifiers such as message names. An attacker can supply a malicious schema that injects arbitrary code into the generated function, which executes when the application processes a message using that schema. This grants access to environment variables, credentials, databases, and internal systems, and allows lateral movement within infrastructure. The flaw affects protobuf.js versions 8.0.0/7.5.4 and lower.

Business & Infrastructure Threats

Cross-tenant helpdesk impersonation to data exfiltration

Threat actors are initiating cross-tenant Microsoft Teams communications while impersonating IT or helpdesk personnel to socially engineer users into granting remote desktop access through Quick Assist or similar remote support tools. After access is established, attackers execute trusted vendor-signed applications alongside attacker-supplied modules to enable malicious code execution. This access pathway is being used for credential-backed lateral movement using Windows Remote Management (WinRM), allowing threat actors to pivot toward domain controllers. In observed intrusions, commercial remote management software and data transfer utilities such as Rclone were deployed to expand access across the enterprise and stage business-relevant data for transfer to external cloud storage. The intrusion chain relies heavily on legitimate applications and administrative protocols, allowing threat actors to blend into expected enterprise activity. Attacks abuse external collaboration features where an attacker from a separate tenant initiates contact while impersonating internal support personnel. While Teams includes external-sender labeling and Accept/Block prompts, this attack chain relies on convincing users to bypass those warnings and voluntarily grant remote access.

Tax documents for school employees potentially stolen across Los Angeles County

The Los Angeles County Office of Education is investigating fraudulent tax return filings affecting employees at school districts across the county after teachers and administrators received letters indicating fraudulent tax filings had been submitted in their names. LACOE manages payroll services for more than 150,000 employees across 100 school districts, community colleges, and charter schools in Los Angeles County. The full scope of the potential data breach is not immediately available. Bellflower Unified School District appeared on the Rhysida gang's dark web leak site on October 28, 2025, with attackers claiming 4.5 TB of data comprising 2,322,764 files. All data was leaked, and DataBreaches.net found files with W-2 and other tax-related information in the data tranche. The district's notice claimed that sensitive staff and student data were stored separately in externally hosted systems and was not impacted, but DataBreaches.net found student and employee payroll/tax data in the leaked data. There is no confirmation that employees were ever notified that their information had been acquired and leaked.

General Security News

Microsoft Teams right-click paste broken by Edge update bug

Microsoft is warning that a recent Microsoft Edge browser update introduced a bug that breaks right-click paste in chats in the Microsoft Teams desktop client. Users report that they are unable to paste URLs, text, or images into Teams chats when using right-click context menus, with the "Paste" option greyed out. The bug is caused by a recent browser update that introduced a code regression in Microsoft Edge, which Microsoft Teams uses for certain functionality. Admins report the problem is affecting users in corporate environments on version 26072.519.4556.7438. Reinstalling Teams or clearing the cache did not fix the problem.

Ruby Central in 'real financial jeopardy' following RubyGems maintainer ruckus

Ruby Central, a nonprofit that supports the Ruby programming language ecosystem, is in "real financial jeopardy" according to board members. The organization has parted ways with its executive director, PR agency, CFO, and concluded several contractor engagements. Board members said finances became "overly dependent on the optimistic timing of when funds may be received against fixed timelines for when our expenses are due." This follows a spat where Ruby Central removed long-standing maintainers who launched a rival Gem Cooperative and created gem.coop. Former maintainers claimed they were removed without notice from RubyGems and Bundler ecosystems without consent. The board voted in April to transition from a governing board to a volunteer working board, with board members taking on direct roles and responsibilities. The board promised to strengthen the security and reliability of RubyGems and rebuild trust across the community.

Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware

Hackers have targeted Ukrainian hospitals and local government bodies in an espionage campaign using malware dubbed AgingFly. Ukraine's CERT-UA said the activity was carried out by a group tracked as UAC-0247, which launched multiple attacks over the past two months against municipal authorities, clinical hospitals, and emergency medical services. The hackers attempted to steal sensitive data and, in some cases, exploit compromised systems to mine cryptocurrency.

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform's disruption. The post notes a surge in attacks as components are integrated into other phishing frameworks.

Judge lets state auditor's investigation into data breach affecting Blue Cross Blue Shield members move forward

A Montana state district judge dismissed a lawsuit from BCBSMT's parent company, Health Care Service Corporation, allowing the Montana State Auditor's Office to move forward with its investigation into a Conduent data breach that affected 462,000 members. HCSC had argued the audit was unwarranted because the new law establishing the obligation to notify the state had gone into effect on October 1, and the breach and BCBSMT's awareness occurred before the new law was in effect. State Auditor James Brown said the ruling reaffirms his regulatory authority to investigate whether laws may have been broken by companies doing business in Montana in the insurance field.

Patch Priority

Vulnerability Disclosures

CVE-2026-4786: Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Microsoft published information on CVE-2026-4786, an incomplete mitigation of CVE-2026-4519 involving %action expansion for command injection to webbrowser.open(). EPSS scores are extremely low: CVE-2026-4519 at 0.000 (6th percentile), CVE-2026-4786 at 0.000 (3rd percentile).

CVE-2026-5160

Microsoft published information on CVE-2026-5160. No details are available beyond the information publication. EPSS is 0.000 (11th percentile).

CVE-2026-6100: Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile

Microsoft published information on CVE-2026-6100, a use-after-free vulnerability in Python's lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure. EPSS is 0.001 (20th percentile).

NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support

NAKIVO announced version 11.2 of its Backup & Replication software, focused on automated real-time replication, support for VMware vSphere 9 and Proxmox VE 9.0/9.1, and OAuth 2.0 authentication. The release adds an automated real-time replication engine that keeps replica VMs synchronized with production workloads, allowing failover to a recent replica within minutes after hardware failures, ransomware, or human error. For VMware environments, v11.2 delivers complete production-ready support for vSphere 9 including vCenter Server 9.0.1.0, ESXi 9.0.1.0, and VDDK 9.0.1.0, with all core capabilities operational (agentless image-based backup and replication using Changed Block Tracking, instant VM recovery, granular file-level and application-object recovery, DR orchestration, ransomware resilience through immutable backups, AES-256 encryption, air-gapped copies, and pre-recovery malware scanning). For Proxmox environments, v11.2 brings full compatibility with Proxmox VE 9.0 and 9.1.

Trends & Context

Cross-tenant collaboration abuse is emerging as a social engineering vector that bypasses traditional email security controls. Attackers leverage the perceived legitimacy of enterprise platforms like Microsoft Teams to establish initial access, then pivot through legitimate administrative protocols. The protobuf.js RCE demonstrates the supply chain risk from widely deployed npm packages with dynamic code generation, particularly when schema inputs are treated as trusted. Ransomware data leaks continue to create downstream consequences months after initial compromise, as demonstrated by the potential connection between the Bellflower USD Rhysida leak from October 2025 and current fraudulent tax filings across Los Angeles County school districts.